GHSA-jfcv-jv9g-2vx2

Suggest an improvement
Source
https://github.com/advisories/GHSA-jfcv-jv9g-2vx2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-jfcv-jv9g-2vx2/GHSA-jfcv-jv9g-2vx2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jfcv-jv9g-2vx2
Aliases
  • CVE-2025-9341
Published
2025-08-22T09:30:41Z
Modified
2025-08-22T20:57:26.252877Z
Severity
  • 5.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:C/RE:M/U:Amber CVSS Calculator
Summary
Bouncy Castle for Java has Uncontrolled Resource Consumption Vulnerability
Details

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files org/bouncycastle/crypto/fips/AESNativeCBC.Java.

This issue affects Bouncy Castle for Java FIPS: from BC-FJA 2.1.0 through 2.1.0.

Database specific
{
    "severity": "MODERATE",
    "nvd_published_at": "2025-08-22T09:15:34Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-400"
    ],
    "github_reviewed_at": "2025-08-22T20:30:47Z"
}
References

Affected packages

Maven / org.bouncycastle:bc-fips

Package

Name
org.bouncycastle:bc-fips
View open source insights on deps.dev
Purl
pkg:maven/org.bouncycastle/bc-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1.0
Fixed
2.1.1

Affected versions

2.*

2.1.0

Maven / org.bouncycastle:bctls-fips

Package

Name
org.bouncycastle:bctls-fips
View open source insights on deps.dev
Purl
pkg:maven/org.bouncycastle/bctls-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.73.7
Fixed
2.73.8

Affected versions

2.*

2.73.7